Sceawere
Vulnerability Detail
CVE-2026-102293UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Improper Authorization in tacomall OrgStaffServiceImpl
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 1h ago
- Vendor
- realjerrytang
- Product
- tacomall
- Attack Type
- Improper Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-29T06:16:58.543Z",
"pubdate": "2026-09-29T06:16:58.543Z",
"executiveSummary": "A critical improper authorization vulnerability exists in the api-admin component of realjerrytang tacomall version 1.0.0.\nThe vulnerability resides within the OrgStaffServiceImpl.add function, which improperly handles authorization logic during staff creation processes.\nBy manipulating specific parameters—specifically isAdmin or jobId—an attacker can bypass existing security access controls to perform unauthorized administrative operations.\nThe vulnerability allows for remote exploitation, enabling malicious actors to escalate privileges or manipulate system data without legitimate authorization.\nGiven that exploit code is publicly available, the risk to deployments of tacomall 1.0.0 is considered high, potentially leading to total administrative compromise of the api-admin backend.\nSuccessful exploitation does not necessarily require complex environmental conditions, making it an attractive target for automated or manual exploitation.",
"technicalDetails": "The vulnerability is an Improper Authorization flaw identified within the OrgStaffServiceImpl.add method located in the ApiMaApplication.java file of the api-admin backend component.\nThe root cause of this vulnerability is the failure of the application to properly validate or sanitize the isAdmin and jobId input arguments during the execution of staff addition requests.\nIn the context of this architecture, the OrgStaffServiceImpl.add function acts as a critical entry point for creating new organizational staff records. The application logic incorrectly trusts the client-provided values for these parameters without enforcing server-side authorization checks to verify if the requesting user possesses the requisite administrative rights to modify these fields.\nThe attack flow proceeds as follows: An attacker intercepts a request intended for the staff addition endpoint. By modifying the payload to include manipulated values for 'isAdmin' or 'jobId', the attacker can craft requests that force the application to assign elevated privileges or specific job designations to an account under the attacker's control.\nBecause the backend function fails to validate these inputs against the session's active security context, the manipulated data is persisted into the database with elevated status. This bypasses the intended business logic where only authenticated users with specific administrative roles should be permitted to manipulate these fields.\nExploitation is facilitated by the lack of defensive parameterization or secondary authorization verification within the ApiMaApplication.java business layer. Since the exploit is publicly available, attackers can leverage automated tooling to identify vulnerable instances of tacomall 1.0.0 and execute these calls remotely without needing internal system access.\nPost-exploitation impact includes unauthorized escalation of privilege, allowing an attacker to operate within the administrative dashboard of the tacomall system. This could lead to further unauthorized modifications, data exfiltration, or complete control over the backend services managed by the api-admin component."
}